github-release-management
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external GitHub sources, such as commit messages and pull request descriptions, to automate the generation of changelogs and release notes.
- Ingestion points: Data is fetched via
gh api repos/:owner/:repo/compare/...andgh pr listinSKILL.md. - Boundary markers: No explicit delimiters or instruction-ignore warnings are used when interpolating command outputs into variables like
$CHANGELOG. - Capability inventory: The skill possesses extensive capabilities, including executing shell commands (
Bash), writing files (Write), and creating pull requests via the GitHub CLI. - Sanitization: There is no evidence of sanitization or filtering for the external content retrieved from repository history.
- [EXTERNAL_DOWNLOADS]: Fetches and executes the
claude-flowandclaude-flow@alphautility packages from the npm registry. - Evidence: Multiple instances of
npx claude-flowandnpx claude-flow@alphaare used throughoutSKILL.mdfor release orchestration. - [COMMAND_EXECUTION]: Executes shell commands and utilizes the GitHub CLI (
gh) to perform repository management and deployment tasks. - Evidence: Frequent use of
Bashcalls inSKILL.mdfor git operations, version bumping, and API interactions. - [DYNAMIC_EXECUTION]: Uses dynamic task orchestration and agent spawning to coordinate complex release workflows across multiple environments.
- Evidence: Use of
mcp__claude-flow__task_orchestrateandmcp__claude-flow__agent_spawninSKILL.mdto define agent roles and execution strategies at runtime.
Audit Metadata